None
EN
Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs
['The Hacker News', 'Sep', 'Ravie Lakshmanan']
The Hacker News
The China-aligned threat actor known as Mustang Panda has been observed using an updated version of a backdoor called TONESHELL and a previously undocumented USB worm called SnakeDisk.
"The worm only executes on devices with Thailand-based IP addresses and drops the Yokai backdoor," IBM X-Force researchers Golo Mühr and Joshua Chung said in an analysis published last week.
Also launched using DLL side-loading is a new USB worm called SnakeDisk that shares overlaps with TONEDISK (aka WispRider), another USB worm framework under the TONESHELL family.
SnakeDisk also serves as a conduit to drop Yokai, a backdoor that sets up a reverse shell to execute arbitrary commands.
The use of SnakeDisk and Yokai likely points to a sub-group within Mustang Panda that's hyper-focused on Thailand, while also underscoring the continued evolution and refinement of the threat actor's arsenal.
['snakedisk'
'worm'
'deploys'
'threat'
'usb'
'panda'
'yokai'
'deliver'
'toneshell'
'backdoor'
'targeting'
'mustang'
'using'
'thailand'
'ips'
'malware']